CVE-2011-3481

NONE EPSS 79.8%
Published Sep 14, 201114y ago · Modified Jun 16, 20262w ago
Find Similar
Published Sep 14, 2011 14y ago
Last Modified Jun 16, 2026 2w ago

Description

The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted References header in an e-mail message.

Threat Intelligence

EPSS Exploit Probability
79.8% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 40

VendorProductVersionRange
cmucyrus_imap_server* ≤2.4.10
cmucyrus_imap_server2.0.17any
cmucyrus_imap_server2.1.16any
cmucyrus_imap_server2.1.17any
cmucyrus_imap_server2.1.18any
cmucyrus_imap_server2.2.8any
cmucyrus_imap_server2.2.9any
cmucyrus_imap_server2.2.10any
cmucyrus_imap_server2.2.11any
cmucyrus_imap_server2.2.12any
cmucyrus_imap_server2.2.13any
cmucyrus_imap_server2.2.13p1any
cmucyrus_imap_server2.3.0any
cmucyrus_imap_server2.3.1any
cmucyrus_imap_server2.3.2any
cmucyrus_imap_server2.3.3any
cmucyrus_imap_server2.3.4any
cmucyrus_imap_server2.3.5any
cmucyrus_imap_server2.3.6any
cmucyrus_imap_server2.3.7any
cmucyrus_imap_server2.3.8any
cmucyrus_imap_server2.3.9any
cmucyrus_imap_server2.3.10any
cmucyrus_imap_server2.3.11any
cmucyrus_imap_server2.3.12any
cmucyrus_imap_server2.3.13any
cmucyrus_imap_server2.3.14any
cmucyrus_imap_server2.3.15any
cmucyrus_imap_server2.3.16any
cmucyrus_imap_server2.3.17any
cmucyrus_imap_server2.4.0any
cmucyrus_imap_server2.4.1any
cmucyrus_imap_server2.4.2any
cmucyrus_imap_server2.4.3any
cmucyrus_imap_server2.4.4any
cmucyrus_imap_server2.4.5any
cmucyrus_imap_server2.4.6any
cmucyrus_imap_server2.4.7any
cmucyrus_imap_server2.4.8any
cmucyrus_imap_server2.4.9any

References 6

Remediation

  • git.cyrusimap.org http://git.cyrusimap.org/cyrus-imapd/commit/?id=6e776956a1a9dfa58eacdd0ddd52644009eac9e5
    Patch